Status reporting is built in making reports available for both executive management and the risk and audit committee. The control effectiveness can be systematically examined to understand the criticality of the control.
- Preventative controls aimed at reducing the likelihood of an incident or adverse event occurring.
- Detective, controls that identify failures in the current controlled environment.
- Corrective controls to reduce the consequence or rectifying a failure that may have been identified.
- Treatment plans are initiatives that are tracked through the framework to follow the progress of the implementation.
- Example Control Report